Oracle Linux 7 : GNOME (ELSA-2018-3140)

critical Nessus Plugin ID 181106

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2018-3140 advisory.

- The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
(CVE-2017-18267)

- There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. (CVE-2018-10733)

- There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack. (CVE-2018-10767)

- There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected. (CVE-2018-10768)

- The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. (CVE-2018-12910)

- Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
(CVE-2018-13988)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2018-3140.html

Plugin Details

Severity: Critical

ID: 181106

File Name: oraclelinux_ELSA-2018-3140.nasl

Version: 1.0

Type: local

Agent: unix

Published: 9/7/2023

Updated: 9/7/2023

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-12910

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:oracle:linux:7, p-cpe:/a:oracle:linux:packagekit, p-cpe:/a:oracle:linux:packagekit-command-not-found, p-cpe:/a:oracle:linux:packagekit-cron, p-cpe:/a:oracle:linux:packagekit-glib, p-cpe:/a:oracle:linux:packagekit-glib-devel, p-cpe:/a:oracle:linux:packagekit-gstreamer-plugin, p-cpe:/a:oracle:linux:packagekit-gtk3-module, p-cpe:/a:oracle:linux:packagekit-yum, p-cpe:/a:oracle:linux:packagekit-yum-plugin, p-cpe:/a:oracle:linux:accountsservice, p-cpe:/a:oracle:linux:evolution-data-server-perl, p-cpe:/a:oracle:linux:evolution-data-server-tests, p-cpe:/a:oracle:linux:evolution-devel, p-cpe:/a:oracle:linux:evolution-devel-docs, p-cpe:/a:oracle:linux:evolution-ews, p-cpe:/a:oracle:linux:evolution-ews-langpacks, p-cpe:/a:oracle:linux:evolution-help, p-cpe:/a:oracle:linux:evolution-langpacks, p-cpe:/a:oracle:linux:evolution-mapi, p-cpe:/a:oracle:linux:evolution-mapi-langpacks, p-cpe:/a:oracle:linux:evolution-pst, p-cpe:/a:oracle:linux:evolution-spamassassin, p-cpe:/a:oracle:linux:evolution-tests, p-cpe:/a:oracle:linux:file-roller, p-cpe:/a:oracle:linux:file-roller-nautilus, p-cpe:/a:oracle:linux:flatpak, p-cpe:/a:oracle:linux:flatpak-builder, p-cpe:/a:oracle:linux:flatpak-devel, p-cpe:/a:oracle:linux:flatpak-libs, p-cpe:/a:oracle:linux:folks, p-cpe:/a:oracle:linux:folks-devel, p-cpe:/a:oracle:linux:folks-tools, p-cpe:/a:oracle:linux:fontconfig, p-cpe:/a:oracle:linux:fontconfig-devel, p-cpe:/a:oracle:linux:fontconfig-devel-doc, p-cpe:/a:oracle:linux:freetype, p-cpe:/a:oracle:linux:freetype-demos, p-cpe:/a:oracle:linux:freetype-devel, p-cpe:/a:oracle:linux:fribidi, p-cpe:/a:oracle:linux:fribidi-devel, p-cpe:/a:oracle:linux:fwupd, p-cpe:/a:oracle:linux:fwupd-devel, p-cpe:/a:oracle:linux:fwupdate, p-cpe:/a:oracle:linux:accountsservice-devel, p-cpe:/a:oracle:linux:accountsservice-libs, p-cpe:/a:oracle:linux:adwaita-cursor-theme, p-cpe:/a:oracle:linux:adwaita-gtk2-theme, p-cpe:/a:oracle:linux:adwaita-icon-theme, p-cpe:/a:oracle:linux:adwaita-icon-theme-devel, p-cpe:/a:oracle:linux:appstream-data, p-cpe:/a:oracle:linux:at-spi2-atk, p-cpe:/a:oracle:linux:at-spi2-atk-devel, p-cpe:/a:oracle:linux:at-spi2-core, p-cpe:/a:oracle:linux:at-spi2-core-devel, p-cpe:/a:oracle:linux:atk, p-cpe:/a:oracle:linux:atk-devel, p-cpe:/a:oracle:linux:baobab, p-cpe:/a:oracle:linux:bolt, p-cpe:/a:oracle:linux:brasero, p-cpe:/a:oracle:linux:brasero-devel, p-cpe:/a:oracle:linux:brasero-libs, p-cpe:/a:oracle:linux:brasero-nautilus, p-cpe:/a:oracle:linux:cairo, p-cpe:/a:oracle:linux:cairo-devel, p-cpe:/a:oracle:linux:cairo-gobject, p-cpe:/a:oracle:linux:cairo-gobject-devel, p-cpe:/a:oracle:linux:cairo-tools, p-cpe:/a:oracle:linux:cheese, p-cpe:/a:oracle:linux:cheese-libs, p-cpe:/a:oracle:linux:cheese-libs-devel, p-cpe:/a:oracle:linux:clutter-gst3, p-cpe:/a:oracle:linux:clutter-gst3-devel, p-cpe:/a:oracle:linux:compat-exiv2-023, p-cpe:/a:oracle:linux:compat-libical1, p-cpe:/a:oracle:linux:control-center, p-cpe:/a:oracle:linux:control-center-filesystem, p-cpe:/a:oracle:linux:dconf, p-cpe:/a:oracle:linux:dconf-devel, p-cpe:/a:oracle:linux:dconf-editor, p-cpe:/a:oracle:linux:devhelp, p-cpe:/a:oracle:linux:devhelp-devel, p-cpe:/a:oracle:linux:devhelp-libs, p-cpe:/a:oracle:linux:ekiga, p-cpe:/a:oracle:linux:empathy, p-cpe:/a:oracle:linux:eog, p-cpe:/a:oracle:linux:eog-devel, p-cpe:/a:oracle:linux:evince, p-cpe:/a:oracle:linux:evince-browser-plugin, p-cpe:/a:oracle:linux:evince-devel, p-cpe:/a:oracle:linux:evince-dvi, p-cpe:/a:oracle:linux:evince-libs, p-cpe:/a:oracle:linux:evince-nautilus, p-cpe:/a:oracle:linux:evolution, p-cpe:/a:oracle:linux:evolution-bogofilter, p-cpe:/a:oracle:linux:evolution-data-server, p-cpe:/a:oracle:linux:evolution-data-server-devel, p-cpe:/a:oracle:linux:evolution-data-server-doc, p-cpe:/a:oracle:linux:evolution-data-server-langpacks, p-cpe:/a:oracle:linux:gedit-plugins, p-cpe:/a:oracle:linux:gedit-plugins-data, p-cpe:/a:oracle:linux:geoclue2, p-cpe:/a:oracle:linux:geoclue2-demos, p-cpe:/a:oracle:linux:geoclue2-devel, p-cpe:/a:oracle:linux:geoclue2-libs, p-cpe:/a:oracle:linux:geocode-glib, p-cpe:/a:oracle:linux:geocode-glib-devel, p-cpe:/a:oracle:linux:gjs, p-cpe:/a:oracle:linux:gjs-devel, p-cpe:/a:oracle:linux:gjs-tests, p-cpe:/a:oracle:linux:glade, p-cpe:/a:oracle:linux:glade-devel, p-cpe:/a:oracle:linux:glade-libs, p-cpe:/a:oracle:linux:glib-networking, p-cpe:/a:oracle:linux:glib-networking-tests, p-cpe:/a:oracle:linux:glib2, p-cpe:/a:oracle:linux:glib2-devel, p-cpe:/a:oracle:linux:glib2-doc, p-cpe:/a:oracle:linux:glib2-fam, p-cpe:/a:oracle:linux:glib2-static, p-cpe:/a:oracle:linux:glib2-tests, p-cpe:/a:oracle:linux:glibmm24, p-cpe:/a:oracle:linux:glibmm24-devel, p-cpe:/a:oracle:linux:glibmm24-doc, p-cpe:/a:oracle:linux:gnome-backgrounds, p-cpe:/a:oracle:linux:gnome-bluetooth, p-cpe:/a:oracle:linux:gnome-bluetooth-libs, p-cpe:/a:oracle:linux:gnome-bluetooth-libs-devel, p-cpe:/a:oracle:linux:gnome-boxes, p-cpe:/a:oracle:linux:gnome-calculator, p-cpe:/a:oracle:linux:gnome-classic-session, p-cpe:/a:oracle:linux:gnome-clocks, p-cpe:/a:oracle:linux:gnome-color-manager, p-cpe:/a:oracle:linux:gnome-contacts, p-cpe:/a:oracle:linux:gnome-desktop3, p-cpe:/a:oracle:linux:gnome-desktop3-devel, p-cpe:/a:oracle:linux:gnome-desktop3-tests, p-cpe:/a:oracle:linux:gnome-devel-docs, p-cpe:/a:oracle:linux:gnome-dictionary, p-cpe:/a:oracle:linux:gnome-disk-utility, p-cpe:/a:oracle:linux:gnome-documents, p-cpe:/a:oracle:linux:gnome-documents-libs, p-cpe:/a:oracle:linux:gnome-font-viewer, p-cpe:/a:oracle:linux:gnome-getting-started-docs, p-cpe:/a:oracle:linux:fwupdate-devel, p-cpe:/a:oracle:linux:fwupdate-efi, p-cpe:/a:oracle:linux:fwupdate-libs, p-cpe:/a:oracle:linux:gcr, p-cpe:/a:oracle:linux:gcr-devel, p-cpe:/a:oracle:linux:gdk-pixbuf2, p-cpe:/a:oracle:linux:gdk-pixbuf2-devel, p-cpe:/a:oracle:linux:gdk-pixbuf2-tests, p-cpe:/a:oracle:linux:gdm, p-cpe:/a:oracle:linux:gdm-devel, p-cpe:/a:oracle:linux:gdm-pam-extensions-devel, p-cpe:/a:oracle:linux:gedit, p-cpe:/a:oracle:linux:gedit-devel, p-cpe:/a:oracle:linux:gedit-plugin-bookmarks, p-cpe:/a:oracle:linux:gedit-plugin-bracketcompletion, p-cpe:/a:oracle:linux:gedit-plugin-charmap, p-cpe:/a:oracle:linux:gedit-plugin-codecomment, p-cpe:/a:oracle:linux:gedit-plugin-colorpicker, p-cpe:/a:oracle:linux:gedit-plugin-colorschemer, p-cpe:/a:oracle:linux:gedit-plugin-commander, p-cpe:/a:oracle:linux:gedit-plugin-drawspaces, p-cpe:/a:oracle:linux:gedit-plugin-findinfiles, p-cpe:/a:oracle:linux:gedit-plugin-joinlines, p-cpe:/a:oracle:linux:gedit-plugin-multiedit, p-cpe:/a:oracle:linux:gedit-plugin-smartspaces, p-cpe:/a:oracle:linux:gedit-plugin-synctex, p-cpe:/a:oracle:linux:gedit-plugin-terminal, p-cpe:/a:oracle:linux:gedit-plugin-textsize, p-cpe:/a:oracle:linux:gedit-plugin-translate, p-cpe:/a:oracle:linux:gedit-plugin-wordcompletion, p-cpe:/a:oracle:linux:gnome-getting-started-docs-cs, p-cpe:/a:oracle:linux:gnome-getting-started-docs-de, p-cpe:/a:oracle:linux:gnome-getting-started-docs-es, p-cpe:/a:oracle:linux:gnome-getting-started-docs-fr, p-cpe:/a:oracle:linux:gnome-getting-started-docs-gl, p-cpe:/a:oracle:linux:gnome-getting-started-docs-hu, p-cpe:/a:oracle:linux:gnome-getting-started-docs-it, p-cpe:/a:oracle:linux:gnome-getting-started-docs-pl, p-cpe:/a:oracle:linux:gnome-getting-started-docs-pt_br, p-cpe:/a:oracle:linux:gnome-getting-started-docs-ru, p-cpe:/a:oracle:linux:gnome-initial-setup, p-cpe:/a:oracle:linux:gnome-keyring, p-cpe:/a:oracle:linux:gnome-keyring-pam, p-cpe:/a:oracle:linux:gnome-online-accounts, p-cpe:/a:oracle:linux:gnome-online-accounts-devel, p-cpe:/a:oracle:linux:gnome-online-miners, p-cpe:/a:oracle:linux:gnome-packagekit, p-cpe:/a:oracle:linux:gnome-packagekit-common, p-cpe:/a:oracle:linux:gnome-packagekit-installer, p-cpe:/a:oracle:linux:gnome-packagekit-updater, p-cpe:/a:oracle:linux:gnome-screenshot, p-cpe:/a:oracle:linux:gnome-session, p-cpe:/a:oracle:linux:gnome-session-custom-session, p-cpe:/a:oracle:linux:gnome-session-wayland-session, p-cpe:/a:oracle:linux:gnome-session-xsession, p-cpe:/a:oracle:linux:gnome-settings-daemon, p-cpe:/a:oracle:linux:gnome-settings-daemon-devel, p-cpe:/a:oracle:linux:gnome-shell, p-cpe:/a:oracle:linux:gnome-shell-extension-alternate-tab, p-cpe:/a:oracle:linux:gnome-shell-extension-apps-menu, p-cpe:/a:oracle:linux:gnome-shell-extension-auto-move-windows, p-cpe:/a:oracle:linux:gnome-shell-extension-common, p-cpe:/a:oracle:linux:gnome-shell-extension-dash-to-dock, p-cpe:/a:oracle:linux:gnome-shell-extension-drive-menu, p-cpe:/a:oracle:linux:gnome-shell-extension-launch-new-instance, p-cpe:/a:oracle:linux:gnome-shell-extension-native-window-placement, p-cpe:/a:oracle:linux:gnome-shell-extension-no-hot-corner, p-cpe:/a:oracle:linux:gnome-shell-extension-panel-favorites, p-cpe:/a:oracle:linux:gnome-shell-extension-places-menu, p-cpe:/a:oracle:linux:gnome-shell-extension-screenshot-window-sizer, p-cpe:/a:oracle:linux:gnome-shell-extension-systemmonitor, p-cpe:/a:oracle:linux:gnome-shell-extension-top-icons, p-cpe:/a:oracle:linux:gnome-shell-extension-updates-dialog, p-cpe:/a:oracle:linux:gnome-shell-extension-user-theme, p-cpe:/a:oracle:linux:gnome-shell-extension-window-list, p-cpe:/a:oracle:linux:gnome-shell-extension-windowsnavigator, p-cpe:/a:oracle:linux:gnome-shell-extension-workspace-indicator, p-cpe:/a:oracle:linux:gnome-software, p-cpe:/a:oracle:linux:gnome-software-devel, p-cpe:/a:oracle:linux:gnome-software-editor, p-cpe:/a:oracle:linux:gnome-system-monitor, p-cpe:/a:oracle:linux:gnome-terminal, p-cpe:/a:oracle:linux:gnome-terminal-nautilus, p-cpe:/a:oracle:linux:gnome-themes-standard, p-cpe:/a:oracle:linux:gnome-tweak-tool, p-cpe:/a:oracle:linux:gnome-user-docs, p-cpe:/a:oracle:linux:gnote, p-cpe:/a:oracle:linux:gobject-introspection, p-cpe:/a:oracle:linux:gobject-introspection-devel, p-cpe:/a:oracle:linux:gom, p-cpe:/a:oracle:linux:gom-devel, p-cpe:/a:oracle:linux:google-noto-emoji-color-fonts, p-cpe:/a:oracle:linux:google-noto-emoji-fonts, p-cpe:/a:oracle:linux:grilo, p-cpe:/a:oracle:linux:grilo-devel, p-cpe:/a:oracle:linux:grilo-plugins, p-cpe:/a:oracle:linux:gsettings-desktop-schemas, p-cpe:/a:oracle:linux:gsettings-desktop-schemas-devel, p-cpe:/a:oracle:linux:gspell, p-cpe:/a:oracle:linux:gspell-devel, p-cpe:/a:oracle:linux:gspell-doc, p-cpe:/a:oracle:linux:gssdp, p-cpe:/a:oracle:linux:gssdp-devel, p-cpe:/a:oracle:linux:gssdp-docs, p-cpe:/a:oracle:linux:gssdp-utils, p-cpe:/a:oracle:linux:gstreamer1-plugins-base, p-cpe:/a:oracle:linux:gstreamer1-plugins-base-devel, p-cpe:/a:oracle:linux:gstreamer1-plugins-base-devel-docs, p-cpe:/a:oracle:linux:gstreamer1-plugins-base-tools, p-cpe:/a:oracle:linux:gtk-doc, p-cpe:/a:oracle:linux:gtk-update-icon-cache, p-cpe:/a:oracle:linux:gtk3, p-cpe:/a:oracle:linux:gtk3-devel, p-cpe:/a:oracle:linux:gtk3-devel-docs, p-cpe:/a:oracle:linux:gtk3-immodule-xim, p-cpe:/a:oracle:linux:gtk3-immodules, p-cpe:/a:oracle:linux:gtk3-tests, p-cpe:/a:oracle:linux:gtksourceview3, p-cpe:/a:oracle:linux:gtksourceview3-devel, p-cpe:/a:oracle:linux:gtksourceview3-tests, p-cpe:/a:oracle:linux:gucharmap, p-cpe:/a:oracle:linux:gucharmap-devel, p-cpe:/a:oracle:linux:gucharmap-libs, p-cpe:/a:oracle:linux:gupnp, p-cpe:/a:oracle:linux:gupnp-devel, p-cpe:/a:oracle:linux:gupnp-docs, p-cpe:/a:oracle:linux:gupnp-igd, p-cpe:/a:oracle:linux:libical-glib, p-cpe:/a:oracle:linux:libical-glib-devel, p-cpe:/a:oracle:linux:libical-glib-doc, p-cpe:/a:oracle:linux:libjpeg-turbo, p-cpe:/a:oracle:linux:libjpeg-turbo-devel, p-cpe:/a:oracle:linux:libjpeg-turbo-static, p-cpe:/a:oracle:linux:libjpeg-turbo-utils, p-cpe:/a:oracle:linux:libmediaart, p-cpe:/a:oracle:linux:libmediaart-devel, p-cpe:/a:oracle:linux:libmediaart-tests, p-cpe:/a:oracle:linux:libosinfo, p-cpe:/a:oracle:linux:libosinfo-devel, p-cpe:/a:oracle:linux:libosinfo-vala, p-cpe:/a:oracle:linux:libpeas, p-cpe:/a:oracle:linux:libpeas-devel, p-cpe:/a:oracle:linux:libpeas-gtk, p-cpe:/a:oracle:linux:libpeas-loader-python, p-cpe:/a:oracle:linux:librsvg2, p-cpe:/a:oracle:linux:librsvg2-devel, p-cpe:/a:oracle:linux:librsvg2-tools, p-cpe:/a:oracle:linux:libsecret, p-cpe:/a:oracle:linux:libsecret-devel, p-cpe:/a:oracle:linux:libsoup, p-cpe:/a:oracle:linux:libsoup-devel, p-cpe:/a:oracle:linux:libwayland-client, p-cpe:/a:oracle:linux:libwayland-cursor, p-cpe:/a:oracle:linux:libwayland-egl, p-cpe:/a:oracle:linux:libwayland-server, p-cpe:/a:oracle:linux:libwnck3, p-cpe:/a:oracle:linux:libwnck3-devel, p-cpe:/a:oracle:linux:mozjs52, p-cpe:/a:oracle:linux:mozjs52-devel, p-cpe:/a:oracle:linux:mutter, p-cpe:/a:oracle:linux:mutter-devel, p-cpe:/a:oracle:linux:nautilus, p-cpe:/a:oracle:linux:vino, p-cpe:/a:oracle:linux:vte-profile, p-cpe:/a:oracle:linux:vte291, p-cpe:/a:oracle:linux:vte291-devel, p-cpe:/a:oracle:linux:wayland-devel, p-cpe:/a:oracle:linux:wayland-doc, p-cpe:/a:oracle:linux:gupnp-igd-devel, p-cpe:/a:oracle:linux:gupnp-igd-python, p-cpe:/a:oracle:linux:gvfs, p-cpe:/a:oracle:linux:gvfs-afc, p-cpe:/a:oracle:linux:gvfs-afp, p-cpe:/a:oracle:linux:gvfs-archive, p-cpe:/a:oracle:linux:gvfs-client, p-cpe:/a:oracle:linux:gvfs-devel, p-cpe:/a:oracle:linux:gvfs-fuse, p-cpe:/a:oracle:linux:gvfs-goa, p-cpe:/a:oracle:linux:gvfs-gphoto2, p-cpe:/a:oracle:linux:gvfs-mtp, p-cpe:/a:oracle:linux:gvfs-smb, p-cpe:/a:oracle:linux:gvfs-tests, p-cpe:/a:oracle:linux:harfbuzz, p-cpe:/a:oracle:linux:harfbuzz-devel, p-cpe:/a:oracle:linux:harfbuzz-icu, p-cpe:/a:oracle:linux:json-glib, p-cpe:/a:oracle:linux:json-glib-devel, p-cpe:/a:oracle:linux:json-glib-tests, p-cpe:/a:oracle:linux:libappstream-glib, p-cpe:/a:oracle:linux:libappstream-glib-builder, p-cpe:/a:oracle:linux:libappstream-glib-builder-devel, p-cpe:/a:oracle:linux:libappstream-glib-devel, p-cpe:/a:oracle:linux:libchamplain, p-cpe:/a:oracle:linux:libchamplain-demos, p-cpe:/a:oracle:linux:libchamplain-devel, p-cpe:/a:oracle:linux:libchamplain-gtk, p-cpe:/a:oracle:linux:libcroco, p-cpe:/a:oracle:linux:libcroco-devel, p-cpe:/a:oracle:linux:libgdata, p-cpe:/a:oracle:linux:libgdata-devel, p-cpe:/a:oracle:linux:libgee, p-cpe:/a:oracle:linux:libgee-devel, p-cpe:/a:oracle:linux:libgepub, p-cpe:/a:oracle:linux:libgepub-devel, p-cpe:/a:oracle:linux:libgexiv2, p-cpe:/a:oracle:linux:libgexiv2-devel, p-cpe:/a:oracle:linux:libgnomekbd, p-cpe:/a:oracle:linux:libgnomekbd-devel, p-cpe:/a:oracle:linux:libgovirt, p-cpe:/a:oracle:linux:libgovirt-devel, p-cpe:/a:oracle:linux:libgtop2, p-cpe:/a:oracle:linux:libgtop2-devel, p-cpe:/a:oracle:linux:libgweather, p-cpe:/a:oracle:linux:libgweather-devel, p-cpe:/a:oracle:linux:libgxps, p-cpe:/a:oracle:linux:libgxps-devel, p-cpe:/a:oracle:linux:libgxps-tools, p-cpe:/a:oracle:linux:libical, p-cpe:/a:oracle:linux:libical-devel, p-cpe:/a:oracle:linux:nautilus-devel, p-cpe:/a:oracle:linux:nautilus-extensions, p-cpe:/a:oracle:linux:nautilus-sendto, p-cpe:/a:oracle:linux:openchange, p-cpe:/a:oracle:linux:openchange-client, p-cpe:/a:oracle:linux:openchange-devel, p-cpe:/a:oracle:linux:openchange-devel-docs, p-cpe:/a:oracle:linux:oracle-logos, p-cpe:/a:oracle:linux:osinfo-db, p-cpe:/a:oracle:linux:pango, p-cpe:/a:oracle:linux:pango-devel, p-cpe:/a:oracle:linux:pango-tests, p-cpe:/a:oracle:linux:poppler, p-cpe:/a:oracle:linux:poppler-cpp, p-cpe:/a:oracle:linux:poppler-cpp-devel, p-cpe:/a:oracle:linux:poppler-demos, p-cpe:/a:oracle:linux:poppler-devel, p-cpe:/a:oracle:linux:poppler-glib, p-cpe:/a:oracle:linux:poppler-glib-devel, p-cpe:/a:oracle:linux:poppler-qt, p-cpe:/a:oracle:linux:poppler-qt-devel, p-cpe:/a:oracle:linux:poppler-utils, p-cpe:/a:oracle:linux:python2-gexiv2, p-cpe:/a:oracle:linux:python2-pyatspi, p-cpe:/a:oracle:linux:rest, p-cpe:/a:oracle:linux:rest-devel, p-cpe:/a:oracle:linux:rhythmbox, p-cpe:/a:oracle:linux:rhythmbox-devel, p-cpe:/a:oracle:linux:seahorse-nautilus, p-cpe:/a:oracle:linux:shotwell, p-cpe:/a:oracle:linux:sushi, p-cpe:/a:oracle:linux:totem, p-cpe:/a:oracle:linux:totem-devel, p-cpe:/a:oracle:linux:totem-nautilus, p-cpe:/a:oracle:linux:totem-pl-parser, p-cpe:/a:oracle:linux:totem-pl-parser-devel, p-cpe:/a:oracle:linux:turbojpeg, p-cpe:/a:oracle:linux:turbojpeg-devel, p-cpe:/a:oracle:linux:upower, p-cpe:/a:oracle:linux:upower-devel, p-cpe:/a:oracle:linux:upower-devel-docs, p-cpe:/a:oracle:linux:vala, p-cpe:/a:oracle:linux:vala-devel, p-cpe:/a:oracle:linux:vala-doc, p-cpe:/a:oracle:linux:valadoc, p-cpe:/a:oracle:linux:valadoc-devel, p-cpe:/a:oracle:linux:wayland-protocols-devel, p-cpe:/a:oracle:linux:webkitgtk4, p-cpe:/a:oracle:linux:webkitgtk4-devel, p-cpe:/a:oracle:linux:webkitgtk4-doc, p-cpe:/a:oracle:linux:webkitgtk4-jsc, p-cpe:/a:oracle:linux:webkitgtk4-jsc-devel, p-cpe:/a:oracle:linux:webkitgtk4-plugin-process-gtk2, p-cpe:/a:oracle:linux:xdg-desktop-portal, p-cpe:/a:oracle:linux:xdg-desktop-portal-devel, p-cpe:/a:oracle:linux:xdg-desktop-portal-gtk, p-cpe:/a:oracle:linux:yelp, p-cpe:/a:oracle:linux:yelp-devel, p-cpe:/a:oracle:linux:yelp-libs, p-cpe:/a:oracle:linux:yelp-tools, p-cpe:/a:oracle:linux:yelp-xsl, p-cpe:/a:oracle:linux:yelp-xsl-devel, p-cpe:/a:oracle:linux:zenity

Required KB Items: Host/OracleLinux, Host/RedHat/release, Host/RedHat/rpm-list, Host/local_checks_enabled

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/5/2018

Vulnerability Publication Date: 5/4/2018

Reference Information

CVE: CVE-2017-18267, CVE-2018-10733, CVE-2018-10767, CVE-2018-10768, CVE-2018-12910, CVE-2018-13988